Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
Transient DOS while processing an ANQP message.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
Memory corruption while processing a GP command response.
Possible out of bound read in DRM due to improper buffer length check. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
While waiting for a response to a callback or listener request, non-secure clients can change permissions to shared memory buffers used by HLOS Invoke Call to secure kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Possible integer overflow in RPMB counter due to lack of length check on user provided data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
Stack out-of-bounds write occurs while setting up a cipher device if the provided IV length exceeds the max limit value in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Possible denial of service scenario due to improper handling of group management action frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Reachable assertion is possible while processing peer association WLAN message from host and nonstandard incoming packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Memory corruption in DSP Services during a remote call from HLOS to DSP.
Memory corruption while loading an ELF segment in TEE Kernel.
Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.
Transient DOS may occur while parsing SSID in action frames.
Memory corruption while deinitializing a HDCP session.
Information disclosure may occur while processing the hypervisor log.
There may be information disclosure during memory re-allocation in TZ Secure OS.
memory corruption when an invalid firehose patch command is invoked.
Transient DOS in WLAN Firmware while parsing a NAN management frame.
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
Transient DOS in Modem while allocating DSM items.
Transient DOS in WLAN Firmware while parsing rsn ies.
Information disclosure while handling beacon or probe response frame in STA.
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains IPPROTONONE as the next header.
Transient DOS in WLAN Firmware while parsing a BTM request.
Memory corruption in Core while processing control functions.
Transient DOS while parse fils IE with length equal to 1.